Few people lost admin acess to Gerrit

Bug #1148518 reported by Paul Sokolovsky
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Linaro Android Infrastructure
Fix Released
Critical
Paul Sokolovsky

Bug Description

This mail described the issue:

On 5 March 2013 18:50, Vishal Bhoj <email address hidden> wrote:
>
>
>
> On 5 March 2013 18:46, Bernhard Rosenkränzer
> <email address hidden> wrote:
>>
>> Hi,
>> I just noticed (while trying to push a new branch in binutils) that my
>> access to gerrit has been restricted.
>> I can no longer push new branches, and I'm no longer in the admin group so
>> I can't add myself to Importers anymore to work around this.
>>
>> Was this intentional?
>
> Same here. I have lost my rights in the group. Adding Paul

Hmm...everyone's in the "Administrator" and "Linaro Android Team
Merger." Paul, is something up with Gerrit?

Revision history for this message
Paul Sokolovsky (pfalcon) wrote :

I went to investigate this today morning, logged in as Admin to web ui, found that Vishal had dup accounts (handling of is known issue with Gerrit), but Bero didn't. Then I went to Gerrit ssh command line to follow https://wiki.linaro.org/Platform/Android/Gerrit/DupAccounts process, but didn't get even doing any changes on DB level - after having done

ssh -p 29418 android.git.linaro.org gerrit flush-caches --all

I found I cannot login to command line i/f again, and going to web ui, I saw I'm not a member of admin group there either.

Changed in linaro-android-infrastructure:
milestone: none → 2013.03
assignee: nobody → Paul Sokolovsky (pfalcon)
importance: Undecided → Critical
status: New → In Progress
Revision history for this message
Paul Sokolovsky (pfalcon) wrote :

Ok, there were issues due:

1. http://launchpad.net openid's used instead of https://launchpad.net - at least for the case of my breakage. We have only https: as trusted, so using http: caused account to become untrusted with all the consequences.
2. Possibly, some changes to Luaunchpad OpenID provider side put some OpenID identities into "wrong" state, with similar effect of limited permission set.

The workaround was; in Gerrit, go to "Settings" -> "Identities" and remove any non-primamary openid's (i.e. all which are removable, primary one simply doesn't have checkbox to mark for removal).

Changed in linaro-android-infrastructure:
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.